1.3 Ensure specific whitelisted IP addresses, IP address ranges, and/or domains are set

Information

Access to the SharePoint web application should be restricted to a certain group of users. Typically, this is done through restricting IP addresses to selectively allow known and approved user populations.
Rationale:
Restricting access to the SharePoint site minimizes the risks due to exposure of the application to unknown user populations. Risks including loss of confidentiality and integrity of stored data could be drastically reduced.

NOTE: Nessus has provided the target output to assist in reviewing the benchmark to ensure target compliance.

Solution

Start Internet Information Services (IIS) Manager.
1. Locate the SharePoint Central Administration v4 from the Sites category.
2. Right-click the Web site or Folder, and then click Properties.
3. Click the Directory Security panel.
4. Click Denied Access.
5. To add single IP addresses for whitelisting, click Single computer and enter the whitelisted IP address.
6. To add a range of IP addresses for whitelisting, click Group of computers and enter the whitelisted IP address range.
7. To add a specific domain for whitelisting, click Domains and enter the whitelisted domain.

See Also

https://www.cisecurity.org/benchmark/microsoft_sharepoint/

Item Details

Category: SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|SC-7, CSCv6|14

Plugin: Windows

Control ID: 98cfed4739ec8129ca961fbee6b1760811655266679c4f97f87169fdb139ab16